Author: Yuri Gagarin

Vulnerabilities in LibreOffice that allow the execution of Gstreamer scripts or plugins

Information has been revealed about two vulnerabilities in the free office suite LibreOffice, which have been assigned a high danger level (8.3 out of 10). The issues have been addressed in the recent updates of LibreOffice 7.6.4 and 7.5.9. The first vulnerability (CVE-2023-6186) allows for the execution of arbitrary scripts when a user clicks on a specially added link in the document that triggers built-in macros or internal commands. In certain situations, it was possible to […]

Proposal to shift responsibility for errors in open-source code

James Bottomley from IBM Research, who oversees SCSI and PA-RISC subsystems in the Linux kernel and previously led the technical committee of the Linux Foundation, has proposed a solution to the issue of potentially holding open-source developers accountable for bugs in their code or inadequate vulnerability remediation. The idea is to shift the legal responsibility for mistakes in the source […]

Linux 6.6.6

Greg Kroah-Hartman, apparently not suffering from hexakosioihexekontahexaphobia, has announced the release of the Linux kernel with the mystical number 6.6.6. The only change is the rollback of a fix related to the cfg80211 driver subsystem (the API configuration for wireless connections under the 802.11 standard), which resulted in a series of regressions due to one lost commit. Source: linux.org.ru

Linux Kernel 6.6.6 Update

Greg Kroah-Hartman, who is responsible for maintaining the stable branch of the Linux kernel, has published a significant release of kernel 6.6.6, which proposes one change affecting the cfg80211 wireless stack. The change rolls back the fix that was added in release 6.6.5, which led to regressions because another fix from the 6.7 branch was not transferred along with the fix in 6.6.5 […]

Vulnerabilities in Buildroot allowing code execution on the build server via a MITM attack

In the Buildroot build system, aimed at creating bootable Linux environments for embedded systems, six vulnerabilities have been identified that allow for alterations in the generated system images or execution of code at the build system level during transit traffic interception (MITM). The vulnerabilities have been addressed in the Buildroot releases 2023.02.8, 2023.08.4, and 2023.11. The first five vulnerabilities (CVE-2023-45841, CVE-2023-45842, CVE-2023-45838, CVE-2023-45839, CVE-2023-45840) affect […]

The OpenBao project has started the development of a fork of Hashicorp Vault

Under the auspices of the Linux Foundation, the OpenBao project has been established, which will continue the development of the Hashicorp Vault codebase under the free MPLv2 (Mozilla Public License). This fork was created in response to HashiCorp's transition of its products to a proprietary BSL 1.1 license, which restricts code usage in cloud systems competing with HashiCorp's products and services. The creators of OpenBao aim to continue […]

Release of the CMake 3.28 build system

The release of the cross-platform open build script generator CMake 3.28 has been announced, serving as an alternative to Autotools and utilized in projects such as KDE, LLVM/Clang, MySQL, MariaDB, ReactOS, and Blender. CMake is notable for providing a simple scripting language, extending functionality through modules, supporting caching, offering tools for cross-compilation, and generating build files for a wide range of build systems and compilers […]

Official announcement regarding the upcoming release of Lubuntu version 24.04 LTS.

On December 9, the developers of the Lubuntu distribution shared some plans for the upcoming Lubuntu 24.04 LTS release. In this version of the distribution, which is set to be released in April, an additional Wayland session is planned to be created. This session will not be installed by default; however, starting from version 24.10, Wayland will be used as the standard option. The Lubuntu developers also hope to fully switch […]

Data corruption in Ext4 under LTS kernel branch 6.1.X.

Due to a problematic patch that was backported from Linux 6.5 to 6.1, causing interference between Ext4 code and iomap, there is a risk of data corruption in older kernels — especially in the latest point releases of Linux 6.1 LTS, which can currently be found in distributions such as Debian 12. The potential bug related to EXT4 filesystem data corruption is encountered […]

Linux Mint 21.3 is available for beta testing

Starting from December 10, 2024, the beta version of Linux Mint 21.3, codenamed 'Virginia', will be available for download. Some changes include the Snap Store being disabled. For more information or instructions on how to re-enable it, you can find it at this link. Guest sessions. You can enable guest sessions in the 'Login Window' utility, but this option is currently turned off by default. Touchpad drivers. In this release […]

New versions of browsers SeaMonkey 2.53.18, Qutebrowser 3.1.0, and Tor Browser 13.0.6

The release of the SeaMonkey 2.53.18 internet application suite has taken place, which consolidates a web browser, an email client, an RSS/Atom feed aggregator, and a WYSIWYG HTML page editor called Composer into a single product. Pre-installed add-ons include the IRC client Chatzilla, the DOM Inspector web development tools, and the Lightning calendar-planner. This new release includes fixes and changes from the current Firefox codebase (SeaMonkey 2.53 is based on […]

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster